Exam CISM All QuestionsBrowse all questions from this exam
Question 571

A new law requires an organization to implement specific security controls. Which of the following should the information security manager do FIRST?

    Correct Answer: B

    The first step an information security manager should take when a new law requires specific security controls is to perform a gap analysis on the new requirements. This involves comparing the current state of the organization's security controls with the new legal requirements to identify any disparities or deficiencies. This process is crucial as it helps to pinpoint the exact areas that need attention to ensure compliance. Once the gap analysis is completed, the organization will have a clear understanding of what needs to be addressed, which can then inform subsequent steps like updating the security policy, developing an implementation plan, and assessing the risk of noncompliance.

Discussion
AlexJacobsonOption: D

As others have said - first D, then other stuff (if necessary; maybe management decides that it's more cost-effective to pay fines then to implement controls).

BroesweeliesOption: B

The first thing the information security manager should do is perform a gap analysis on the new requirements. A gap analysis is a process of comparing the current state of the organization's security against the new legal requirements to identify any areas where the organization falls short of meeting the new requirements. This step is important to identify the specific areas where the organization needs to improve its security controls in order to comply with the new law. Once the gap analysis is complete, the organization can develop a control implementation plan, integrate the new requirements into the security policy, and assess the risk of noncompliance with the new requirements.

03allenOption: B

Always evaluate how to achieve it first rather than a negative thought about noncompliance.

yottabyteOption: B

Perform a gap analysis is the best bet here.

Marcovic00Option: D

I go with D then B

koala_layOption: B

Performing a gap analysis involves comparing the organization's current security controls and practices against the specific security controls mandated by the new law. This analysis will identify any gaps or areas where the organization does not meet the requirements.

kristofer8Option: D

D no other option!

richck102Option: B

B. Perform a gap analysis on the new requirements.